boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-74

Weakness type CWE-74 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
5265242

Monthly trend

▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▄█▆▆

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 2 · 2026-03 1 · 2026-04 0 · 2026-05 82 · 2026-06 171 · 2026-07 134 · 2026-08 134

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2019-27259.8100.0KEVOracle WebLogic Server
CVE-2022-279247.599.7KEVSynacor Zimbra Collaboration Suite (ZCS)
CVE-2026-100602.191.6TRENDnet TEW-432BRP formSetRoute command injection
CVE-2026-100612.191.6TRENDnet TEW-432BRP formWPS command injection
CVE-2026-108782.190.2D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
CVE-2026-113392.186.8D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection
CVE-2026-188147.384.8H3C NX15 esps reload.reload_config command injection
CVE-2026-186868.984.2GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
CVE-2026-193488.983.2Shenzhen Aitemi M300 Wi-Fi Repeater protocol.csp sprintf command injection
CVE-2026-121977.382.6Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
CVE-2026-189027.382.6H3C NX15 esps repeaterproc command injection
CVE-2026-186018.982.5GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command inj…
CVE-2026-197478.982.4Tenda CH7 ATE Module Kylin HandleCmd command injection
CVE-2026-188117.381.6H3C NX15 esps add command injection
CVE-2026-188127.381.6H3C NX15 esps esps.ipv6.wan command injection
CVE-2026-188137.381.6H3C NX15 esps delete command injection
CVE-2026-193467.481.2Tenda CH22 CertListInfo formCertListInfo command injection
CVE-2026-62799.880.8Avada (Fusion) Builder <= 3.15.2 - Unauthenticated Remote Code Execution via PHP Functi…
CVE-2026-186128.980.7GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection
CVE-2026-94232.080.0Edimax BR-6675nD POST Request mp command injection

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
itsourcecode79
sourcecodester72
code-projects56
codeastro36
edimax23
gl.inet19
microsoft7
nousresearch7
trendnet7
h3c6
gl-inet5
acacode4
apache4
cisco4
jinher4